Juan Tomás Alonso Nieto (Deactivated)
Apr 28, 2023
...
Field
Type
Source field name
Extra fields
eventdate
timestamp
machine
str
vmachine
OPERATION_D
OSTYPE_D
RULE_NAME
DISPOSITION_D
USER_NAME
TARGET_INFO
EVENT_DT
AGENTNAME
EVENT_TYPE_D
HOSTNAME
PROCESS_NAME
POST_DT
DESCRIPTION
EVENT_SEVERITY_D
HOSTADDR
EVENT_ID
int4
EVENT_CATEGORY_D
RESOURCE_NAME
hostchain
✓
tag
rawMessage
PROCESS_PATH
EVENT_TYPE
DOMAIN_NAME
ASSET_RID
POLICY_NAME
EVENT_SEQ
int8
EVENT_SOURCE_D
OSVERSION
ip4
REMOTEIP
LOCALPORT
REMOTEPORT
message
Field transformation
srcHost
serverdate
eventId
sourceName
username
logType
category
threat
(eventId = 9) ? trim(subs(message, "(.*)Risk name:([^,]*+),(.*)", "\\2")) : null("")
action
(eventId = 9) ? trim(subs(message, "(.*)Actual action:([^,]*+),(.*)", "\\2")) : null("")